Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vicidial

First CVE: Jun 27, 2009Active for: 17 yearsTotal CVEs: 10
43.9
VTI Score
High

Vicidial is a narrowly scoped open-source call-center platform whose vulnerability footprint centers on its core product and call-center suite, both web-facing systems handling customer interaction and administrative workflows. The recurring exposure pattern reflects application-layer input handling across web interfaces: SQL injection and cross-site scripting vulnerabilities recur as the durable signal, consistent with the demands of a database-backed web application, while public exploit code frequently becomes available for disclosed flaws. Defenders should treat Vicidial instances as internet-reachable administrative systems and prioritize patching for injection-class vulnerabilities; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vicidial over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2009
17 years ago
Most Recent CVE
Mar 6, 2023
1,236 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-4467MEDIUM
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to e
Mar 11, 20146.559NOYES
CVE-2013-4468MEDIUM
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extensi
May 14, 20146.551NOYES
CVE-2022-34878HIGH
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing d
Jul 5, 20228.840NOYES
CVE-2022-34877HIGH
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper wi
Jul 5, 20228.840NOYES
CVE-2022-34876HIGH
SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spo
Jul 5, 20228.840NOYES
CVE-2013-7382MEDIUM
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for re
May 17, 20145.028NOYES
CVE-2009-2234HIGH
Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter
Jun 27, 20097.528NOYES
CVE-2021-35377MEDIUM
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vici
Mar 6, 20236.122NONO
CVE-2022-34879MEDIUM
Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data paramete
Jul 5, 20226.122NONO
CVE-2021-46557MEDIUM
Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.
Feb 15, 20225.420NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (60.0%)
Unknown4 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High0 (0.0%)
Unknown4 (40.0%)
User Interaction
None3 (30.0%)
Unknown4 (40.0%)
Required3 (30.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None2 (20.0%)
Unknown4 (40.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
50.0% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
40.0% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vicidial.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vicidial — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vicidial's Products

View all 3 CNAs →

Top CWEs